本文へ移動
cccskills
無料GitHub で公開

dependency-update

Bump a Gradle or Rust dependency version. Use when editing libs.versions.toml, native/rust/Cargo.toml, or reviewing a Renovate PR. Not for adding a module or plugin (gradle-build-system, convention-plugin-development).

インストール方法を見る

含まれるファイル(1)

  • SKILL.md5.4 KB

SKILL.md(原文)

インストールする前に、エージェントに与えられる指示の中身を確認できます。

Dependency Update

Two dependency ecosystems (Gradle + Cargo) with Renovate automating PR creation.

Gradle Version Catalog

File: gradle/libs.versions.toml

Values below are illustrative placeholders only -- always read the live pins from gradle/libs.versions.toml before reporting or bumping a version; they change independently of this skill.

Structure:

[versions]
agp = "X.Y.Z"
kotlin-compose = "X.Y.Z"
compose-bom = "YYYY.MM.NN"

[libraries]
androidx-core = { group = "androidx.core", name = "core-ktx", version.ref = "androidxCore" }

[plugins]
android-application = { id = "com.android.application", version.ref = "agp" }

[bundles]
lifecycle = ["lifecycle-runtime", "lifecycle-viewmodel"]

Rule: Always update the version in the [versions] section. Never inline a version in [libraries] or [plugins].

Key Version Groups

GroupVersions to Update Together
Kotlin / Compose pluginkotlin-compose and its compatible KSP entry
Composecompose-bom (single BOM controls Compose libraries)
AndroidXIndividually, but Renovate groups them
AGPagp (may require Gradle wrapper update)
Testingjunit, robolectric, roborazzi independently

Rust Dependencies

File: native/rust/Cargo.toml (workspace root)

Dependencies declared in [workspace.dependencies] are inherited by crates via { workspace = true }:

[workspace.dependencies]
tokio = { version = "1.45", features = ["full"] }
serde = { version = "1", features = ["derive"] }

Update a specific crate:

cd native/rust
cargo update -p tokio

Update all:

cd native/rust
cargo update

Renovate Configuration

File: renovate.json

Grouping rules:

  • AndroidX packages grouped into a single PR
  • Kotlin + Compose Compiler grouped together
  • Static analysis (detekt, ktlint) grouped together
  • All dependency PRs labeled dependencies
  • Git submodules enabled

Update Workflows

Single Gradle Dependency

# 1. Edit version in libs.versions.toml
# 2. Verify
./gradlew assembleDebug && ./gradlew testDebugUnitTest

AGP / Gradle Upgrade

# 1. Update agp version in libs.versions.toml
# 2. May need Gradle wrapper update:
./gradlew wrapper --gradle-version=X.Y.Z
# 3. Full verification:
./gradlew assembleDebug testDebugUnitTest staticAnalysis

Kotlin Version Update

Update all three together in libs.versions.toml:

  • kotlin (Kotlin compiler)
  • ksp (must match Kotlin major.minor)
  • kotlinComposeCompiler (Compose compiler plugin)
./gradlew assembleDebug testDebugUnitTest staticAnalysis

Rust Dependency Update

cd native/rust
cargo update -p <crate-name>
cargo test --locked
cargo clippy --locked --workspace --all-targets -- -D warnings
# Rebuild Android libs to verify cross-compilation:
cd ../.. && ./gradlew :core:engine:buildRustNativeLibs

NDK Version Update

NDK changes affect both ecosystems:

  1. Update ripdpi.nativeNdkVersion in gradle.properties
  2. Verify Rust cross-compilation targets still work:
    ./gradlew :core:engine:buildRustNativeLibs
    
  3. Full test suite:
    ./gradlew assembleDebug testDebugUnitTest
    cd native/rust && cargo test --locked
    

Rust Toolchain Update

  1. Update channel in native/rust/rust-toolchain.toml
  2. Verify CI workflow uses the same version (reads from rust-toolchain.toml)
  3. Run: cd native/rust && cargo test --locked && cargo clippy --locked --workspace

Cross-Ecosystem Dependencies

ChangeAffects
NDK versiongradle.properties + Rust cross-compilation targets
Rust toolchainrust-toolchain.toml + CI workflow setup
JNI API changesKotlin bindings in core/engine + Rust crates ripdpi-android, ripdpi-tunnel-android

Verification Checklist

After any update, run in order:

./gradlew assembleDebug                          # Kotlin compilation
./gradlew testDebugUnitTest                      # Unit tests
./gradlew staticAnalysis                         # detekt + ktlint + lint
cd native/rust && cargo test --locked                     # Rust tests
cd ../.. && ./gradlew :core:engine:buildRustNativeLibs  # Cross-compilation

Common Mistakes

MistakeFix
Inline version in [libraries] instead of [versions]Always use version.ref pointing to [versions] entry
Updating Kotlin without KSPKSP version must match Kotlin major.minor. Update together.
Forgetting Cargo.lockCargo.lock is committed for reproducible builds. Run cargo update and commit the lock file.
NDK update without rebuilding native libsNDK changes require ./gradlew :core:engine:buildRustNativeLibs to verify.
Updating Compose libs individuallyUse composeBom version -- single BOM controls all Compose library versions.
Rust toolchain update without CI checkCI reads rust-toolchain.toml -- verify the version exists and targets are available.

See Also

  • gradle-build-system skill -- convention plugins and dependency management patterns.
  • ci-workflow-authoring skill -- CI environment setup that depends on these versions.

レビュー

まだレビューはありません。使ってみた感想をお寄せください。

同じリポジトリのスキル

概要と使いどころ

RIPDPI's own Compose conventions: ViewModel pattern, Route/Screen split, DataStore->StateFlow, RipDpiThemeTokens. Use for how this app does Compose, not generic Compose API questions (see compose).

日本語の概要は準備中です。原文の説明を表示しています。

po4yka/RIPDPI792026年10月11日 更新

ADB-based RIPDPI device/emulator debugging: build/install/launch, logcat filtering, fixture port-forwarding, instrumented tests, crash/ANR triage. Use when debugging on a real device or emulator.

日本語の概要は準備中です。原文の説明を表示しています。

po4yka/RIPDPI792026年10月11日 更新

RIPDPI Appium launch-contract reference: start routes and permission/service/data presets. Use when a test launches to the wrong screen or a new automation route is added. General flakiness: appium-test-debug.

日本語の概要は準備中です。原文の説明を表示しています。

po4yka/RIPDPI792026年10月11日 更新

RIPDPI Appium test authoring: page objects, resource-id locators, assertions, wait tiers. Use when writing a new Appium test or page object, or adding coverage for a new screen.

日本語の概要は準備中です。原文の説明を表示しています。

po4yka/RIPDPI792026年10月11日 更新

RIPDPI Appium failure triage: flaky tests, locator/session/wait issues, screenshot and element-tree debugging. Use when an Appium test fails or is flaky.

日本語の概要は準備中です。原文の説明を表示しています。

po4yka/RIPDPI792026年10月11日 更新

Add or modify a GitHub Actions job. Use when editing a file under .github/workflows/. Not for running a workflow locally (local-ci-act) or release signing (release-signing).

日本語の概要は準備中です。原文の説明を表示しています。

po4yka/RIPDPI792026年10月11日 更新

po4yka のスキルをすべて見る

このスキルの問題を報告する